#VU80526 Path traversal in Job Configuration History - CVE-2023-41932
Published: September 7, 2023
Job Configuration History
Jenkins
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to the affected plugin does not restrict "timestamp" query parameters in multiple endpoints. A remote user can send a specially crafted HTTP request and delete attacker-specified directories on the Jenkins controller file system.